VORANT. Threat Intelligence Sign in Get the full feed

Unpatched RCE Found in Code Runner MCP Server

medium vulnerability technology

CVE-2026-5029 lets unauthenticated attackers execute arbitrary code on Code Runner MCP Server instances running with HTTP transport, and no fix exists.

CERT Polska coordinated disclosure of CVE-2026-5029, a remote code execution vulnerability in the Code Runner MCP Server. When the server is launched with the --transport http option, it exposes an unauthenticated JSON-RPC endpoint (/mcp) on port 3088. Attackers can invoke the server's run-code tool to submit arbitrary source code, which is executed via child_process.exec() using the specified language interpreter, granting code execution with the privileges of the server process.

The vulnerability affects all versions of the project and has not been patched at time of disclosure. Given that MCP (Model Context Protocol) servers are increasingly deployed to support AI-agent tooling and often exposed for integration purposes, unauthenticated instances running HTTP transport are directly exploitable with no user interaction required. No evidence of active in-the-wild exploitation was reported; the advisory represents a coordinated disclosure rather than confirmation of ongoing attacks. Operators are advised to avoid exposing the HTTP transport without authentication controls until an upstream fix is available.

Mentioned in this report

Vulnerabilities CVE-2026-5029

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-5029

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free